March 2, 2017 By Larry Loeb 2 min read

This week, New York released cybersecurity regulations that monitor required infrastructure for regulated financial services institutions. Though the regulations have been in development for a while, CSO Online reported they were only finalized about a month ago.

A Much-Needed Initiative

The regulations include mandating the establishment of a cybersecurity program within financial institutions. Each companywide program must have an appointed chief information security officer (CISO). The CISO is held responsible for the operation of the program, which is to be run on a risk-assessment model.

This means that decision-making is based on an evaluation of the various risks that present themselves and the process that leads to a decision can be transparently demonstrated to a regulator. Also, the cybersecurity of any business partners must now be entered into the overall risk assessment.

The regulations can get technique-specific. For instance, an annual penetration test will be a criterion, and vulnerability assessments are to be performed twice a year, at minimum. Also, the definition of nonpublic information expands in the regulations to more than what is usually considered confidential. Organizations will have to prove that nonpublic information is protected by cybersecurity efforts.

Increasing Cybersecurity Regulations

The next six months will be a period of transition under the regulations. Richard Santalesa, of the Smartedge Law Group, outlined the deadlines that the regulations mandate in an email.

“The deadline for compliance with many of the Regulations requirements is Sept. 1, 2017, while compliance with the more technical requirements is either March 1, 2018 or Sept. 1, 2018. And the requirements to be imposed upon third-party service providers is now March 1, 2019,” he wrote. “Together the staggered and extended deadlines for compliance should provide entities with a modicum of breathing room to employ requirement measures, procedures and policies.”

Many institutions are now facing some needed efforts in compliance resolution, even though professional organizations have recommended the risk-assessment approach be used in cybersecurity for many years.

Santalesa went on to list what will be expected of financial services institutions. He said they “have six months to review the requirements, update their cybersecurity policy, incident response plan, craft a third-party service provider policy, conduct and document a risk assessment.” Then, by Sept. 1, 2017, those organizations must submit a certification of compliance or exemption.

These New York regulations may end up serving as a model for adoption by other states. Additionally, the effort made to comply with this governance may actually serve an institution well in other jurisdictions, which can lower the overall cost of compliance.

More from

Unpacking the NIST cybersecurity framework 2.0

4 min read - The NIST cybersecurity framework (CSF) helps organizations improve risk management using common language that focuses on business drivers to enhance cybersecurity.NIST CSF 1.0 was released in February 2014, and version 1.1 in April 2018. In February 2024, NIST released its newest CSF iteration: 2.0. The journey to CSF 2.0 began with a request for information (RFI) in February 2022. Over the next two years, NIST engaged the cybersecurity community through analysis, workshops, comments and draft revision to refine existing standards…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Obtaining security clearance: Hurdles and requirements

3 min read - As security moves closer to the top of the operational priority list for private and public organizations, needing to obtain a security clearance for jobs is more commonplace. Security clearance is a prerequisite for a wide range of roles, especially those related to national security and defense.Obtaining that clearance, however, is far from simple. The process often involves scrutinizing one’s background, financial history and even personal character. Let’s briefly explore some of the hurdles, expectations and requirements of obtaining a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today